Network Address Evaluation for Phishing Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network security systems face challenges in accurately identifying and authenticating network addresses, particularly in detecting phishing websites and other malicious sources, as users often struggle to differentiate between legitimate and fraudulent domains due to misleading domain names and IP addresses.

Innovation Solution

The implementation of a system that evaluates network addresses against a list of known trusted addresses, utilizing multiple tiers of security including IP addresses, port numbers, and communication payload properties, to validate communications and provide user involvement in approving or blocking suspicious activities.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If users rely on domain names to identify legitimate websites, then ease of operation is improved, but reliability deteriorates due to phishing websites using misleading domain names

Engineering Contradiction:
Improveease of identifying websitesVSAvoidaccuracy of website identification
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces an intermediary evaluation system that mediates between the user and the website. This system automatically evaluates network addresses by comparing them against trusted address lists and analyzing communication properties, providing an objective reliability assessment that users cannot obtain through manual domain name inspection alone.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces the manual mechanical process of users visually inspecting domain names with an automated electronic evaluation system. This system programmatically analyzes network addresses, port numbers, and communication payloads, substituting human judgment with automated technical evaluation to improve both speed and accuracy.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If multiple tiers of security evaluation are implemented, then reliability is improved, but device complexity increases

Engineering Contradiction:
Improveaccuracy of address validationVSAvoidcomplexity of security system
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the security evaluation into distinct hierarchical tiers: first evaluating the network address against trusted lists, then examining port numbers, and finally analyzing communication payload properties. This segmentation allows each evaluation layer to be independently implemented and managed, reducing overall system complexity while maintaining high reliability.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent performs preliminary evaluation actions by maintaining precompiled lists of trusted network addresses and known malicious patterns. By preparing these reference data sets in advance, the system can quickly compare incoming communications against established criteria without performing complex real-time analysis, thereby improving reliability without proportionally increasing complexity.

Inventive Principle:
Principle #10Preliminary action

3Productivity

If automated evaluation of network addresses is implemented, then productivity is improved, but loss of information increases due to potential false positives

Engineering Contradiction:
Improvespeed of security evaluationVSAvoidaccuracy of security decisions
Core Design Contradiction:
ProductivityVSLoss of information

Solution Approach 1:

The patent incorporates feedback mechanisms where user responses to security evaluations are recorded and used to refine the evaluation system. When users indicate whether blocked communications were legitimate or whether allowed communications were malicious, this feedback adjusts the trusted address lists and evaluation parameters, improving accuracy over time while maintaining automated speed.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent applies partial evaluation actions by allowing communications to proceed through multiple evaluation tiers, with later tiers providing increasingly stringent checks. Not all communications require the full depth of evaluation - trusted addresses undergo simpler checks while unknown addresses receive more rigorous multi-tier scrutiny, balancing speed and accuracy.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS8621604B2Evaluating a questionable network communication
Publication Date: 2013.12.31 CHIEN DANIEL
  • US8621604B2 patent drawing
  • US8621604B2 patent drawing
  • US8621604B2 patent drawing

AI summary

Identifying a questionable network address from a network communication. In an embodiment, a network device receives an incoming or outgoing connection request, a web page, an email, or other network communication. An evaluation module evaluates the network communication for a corresponding network address, which may be for the source or destination of the network communication. The network address generally includes an IP address and a port number. The evaluation module checks a predefined white list for the network address to determine whether the network address is valid. Depending on the result, the evaluation module sets an indicator for preventing, allowing, or warning about the network communication. A category code, security code, organization code, or function code, may also be checked against the white list to ensure a valid network node is not compromised. A domain name may also be determined from the network address to further validate the network communication.